Comment 2 for bug 1929699

Revision history for this message
Vladimir Grevtsev (vlgrevtsev) wrote :

Even after adding the capability manually, the "manila access-allow ..." command fails, complaining about RADOS command error in manila-share.log: https://pastebin.canonical.com/p/JcYDPTGY5F/

In the meanwhile, ceph-mon logs shows the following:

2021-05-27T13:25:03.934+0000 7fdbf9bf1700 0 mon.juju-291059-3-lxd-1@2(peon) e2 handle_command mon_command({"prefix": "auth get", "entity": "client.ganesha-0737adf5-016d-4472-8926-161d6fdf583e", "format": "json"} v 0) v1
2021-05-27T13:25:03.934+0000 7fdbf9bf1700 1 mon.juju-291059-3-lxd-1@2(peon) e2 handle_command access denied
2021-05-27T13:25:03.934+0000 7fdbf9bf1700 0 log_channel(audit) log [INF] : from='client.? 172.16.155.21:0/2708241706' entity='client.manila-ganesha' cmd=[{"prefix": "auth get", "entity": "client.ganesha-0737adf5-016d-4472-8926-161d6fdf583e", "format": "json"}]: access denied
2021-05-27T13:25:03.998+0000 7fdbf9bf1700 0 mon.juju-291059-3-lxd-1@2(peon) e2 handle_command mon_command({"prefix": "auth get-or-create", "entity": "client.ganesha-0737adf5-016d-4472-8926-161d6fdf583e", "caps": ["mds", "allow rw path=/volumes/_nogroup/0737adf5-016d-4472-8926-161d6fdf583e", "osd", "allow rw pool=ceph-fs_data namespace=fsvolumens_0737adf5-016d-4472-8926-161d6fdf583e", "mon", "allow r"], "format": "json"} v 0) v1
2021-05-27T13:25:03.998+0000 7fdbf9bf1700 1 mon.juju-291059-3-lxd-1@2(peon) e2 handle_command access denied
2021-05-27T13:25:03.998+0000 7fdbf9bf1700 0 log_channel(audit) log [INF] : from='client.? 172.16.155.21:0/2708241706' entity='client.manila-ganesha' cmd=[{"prefix": "auth get-or-create", "entity": "client.ganesha-0737adf5-016d-4472-8926-161d6fdf583e", "caps": ["mds", "allow rw path=/volumes/_nogroup/0737adf5-016d-4472-8926-161d6fdf583e", "osd", "allow rw pool=ceph-fs_data namespace=fsvolumens_0737adf5-016d-4472-8926-161d6fdf583e", "mon", "allow r"], "format": "json"}]: access denied